On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities. These affect Check Point Security Gateway, Security Management Server, and Spark Firewall deployments. The vulnerabilities are present in configurations using Remote Access VPN or Site-to-Site VPN. Both vulnerabilities have a CVSS score of 9.8.
On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities. These affect Check Point Security Gateway, Security Management Server, and Spark Firewall deployments. The vulnerabilities are present in configurations using Remote Access VPN or Site-to-Site VPN.
Both vulnerabilities have a CVSS score of 9.8. They could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. This poses a significant security risk to the systems.
CERT-EU strongly recommends applying the available hotfixes as soon as possible. Prioritisation should be given to internet-facing and perimeter appliances to mitigate immediate threats.
